LAO
Nonreporting Entities' Information Security Compliance
Read the report at Legislative Analyst's Office ↗
2023-24 BUDGET
Nonreporting Entities’
Information Security Compliance
GABRIEL PETEK | LEGISLATIVE ANALYST
MARCH 2023
www.lao.ca.gov 1
AN LAO REPORT
2 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
Executive Summary
Report Satisfies Supplemental Report Requirement. The Legislature adopted
supplemental report language (SRL) in 2022 directing our office to publish a report on
nonreporting entities’ information security (IS) compliance. (A nonreporting entity is a state entity
that is not under the direct authority of the Governor and, therefore, generally is considered to
be outside of the California Department of Technology’s [CDT’s] IS authority.) Specifically, the
SRL required the report to identify each of the nonreporting entities, consider whether some of
them could benefit from compliance with and reporting on IS policies and procedures similar to
those set by CDT, and provide options for the Legislature to consider to improve nonreporting
entities’ IS compliance and achieve a certain IS maturity level (that is, how prepared state entities’
IS programs are to prevent and/or respond to a cyberattack and/or threat). The publication of this
report satisfies the requirements of the SRL.
Report Identifies 22 Nonreporting Entities Based on One Statutory Interpretation.
Our office, in consultation with CDT, created a list of nonreporting entities based on one possible
interpretation of state statute. We identified these entities based on specific definitions in statute,
along with reviews of constitutional and statutory authorities for these entities. However, this list
is not definitive or exhaustive as other statutory interpretations, such as a different interpretation
of a state entity’s reporting relationship with the Governor, could add or remove an entity from
the nonreporting entities list. These alternative statutory interpretations highlight a problematic
ambiguity in state IS authority. Therefore, we recommend the Legislature amend statute to clearly
identify which entities are nonreporting for the purposes of IS.
Chapter 773 of 2022 (AB 2135, Irwin) Addresses Some Compliance and Governance
Issues Considered in SRL Report. Assembly Bill 2135 requires nonreporting entities to
perform IS compliance and reporting activities similar to those required of reporting entities.
These include using certain federal authorities for their policies, procedures, and standards;
certifying compliance with IS requirements annually; and undergoing biennial independent
security assessments. While some of the benefits and improvements in nonreporting entities’
IS compliance will depend on AB 2135 implementation, we consider some of the compliance and
governance issues in the SRL to be addressed to a significant extent by AB 2135. The remainder
of our report focuses on the results of our research on nonreporting entities’ IS programs across
the three topics of IS governance, IS compliance, and IS/information technology infrastructure
and staffing.
Evaluation of Nonreporting Entities’ IS Programs Presents Options to Improve Their
Compliance and Maturity. The two figures below summarize (1) the findings of our analysis
and (2) options for legislative action based on those findings. Our analysis included interviewing
34 entities (including 17 of 22 nonreporting entities); meeting with entities in the state’s IS
governance structure; reviewing federal and state IS policies, procedures, and standards; and
assessing nonreporting entity IS documentation.
www.lao.ca.gov 3
AN LAO REPORT
Summary of Findings on Nonreporting Entities’ IS Programs
Topic Findings
IS Governance Significant differences in nonreporting entity functions, roles, and size.
Majority of nonreporting entities cited state IS policies, procedures, and standards as primary framework for IS
programs.
Many nonreporting entities receive and use threat intelligence information from Cal-CSIC, but only some sought
Cal-CSIC and CDT’s guidance on Cal-Secure implementation.
Many nonreporting entities found CDT’s IS resources difficult to use.
Some entities said statutory ambiguity impacted IS program decision-making.
IS Compliance Nearly all nonreporting entities underwent an ISA in the past several years.
Some nonreporting entities voluntarily comply with state IS policies, procedures, and standards.
Some nonreporting entities in voluntary compliance cited a lack of documentation review by CDT.
Some nonreporting entities required to perform additional IS compliance activities by cyber insurance providers.
Some nonreporting entities identified the lack of certification and education opportunities for existing staff to
improve compliance.
IS/IT Infrastructure Several nonreporting entities use CDT IS and IT service offerings, but some nonreporting entities said private
and Staffing vendors offered better levels of service and pricing for IS and IT services.
Nearly all nonreporting entities cited significant challenges hiring, training, and retaining IS staff.
Smaller nonreporting entities raised concerns about procurement delays.
Summary of Options to Improve Nonreporting Entities’ IS Compliance and Maturity
Topic Options
IS Governance Consider amending CDT’s IS authority to address statutory ambiguity of state agency and state entity definitions
and use.
Recommend monitoring nonreporting entities’ compliance with and implementation of AB 2135.a
Consider directing CDT to improve ease of use of IS-related guidance, information, and templates.
Consider directing Cal-CSIC to increase outreach to nonreporting entities implementing Cal-Secure.
IS Compliance Consider opportunities to condition state funding on compliance with federal and state IS policies, procedures,
and standards.
Consider directing Cal-CSIC and CDT to report to the Legislature on Cal-Secure implementation.
Consider requiring CDT to develop centralized IS training hub for IS compliance certification and education.
Consider requiring an evaluation of major cyber insurance products to understand compliance requirements.
IS/IT Infrastructure Consider expanding use of shared service contracts for IS services.
and Staffing Consider directing administration to expand on existing recruitment, training, and retention efforts to increase
size of IS workforce.
Consider monitoring State Data Center rate reassessment process for IT services.
Consider mandating certain network traffic be directed to CDT’s SOC for monitoring.
Consider directing administration to evaluate division of IT procurement responsibilities.
a Chapter 773 of 2022 (AB 2135, Irwin).
IS = information security; Cal-CSIC = California Cybersecurity Integration Center; CDT = California Department of Technology; ISA = independent security
assessment; IT = information technology; and SOC = Security Operations Center.
4 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
INTRODUCTION
Report Satisfies Supplemental Report The publication of this report satisfies the
Requirement. The Legislature adopted requirements of the SRL.
supplemental report language (SRL) in 2022 Report Maintains Confidentiality of
directing our office to publish a report on Information as Required by State Law.
nonreporting entities’ information security (IS) The SRL also required our office to maintain the
compliance. (We define nonreporting entities and confidentiality of the information collected from
provide more information on IS compliance in nonreporting entities in compliance with state law.
the “Background” section.) Specifically, the SRL For example, Government Code Section 7929.210
required the report to, at a minimum, identify each limits disclosure of state IS documents if their
of the nonreporting entities, consider whether some disclosure “would reveal vulnerabilities to, or
of them could benefit from compliance with and otherwise increase the potential for an attack
reporting on IS policies and procedures similar to on,” state information technology (IT) systems.
those set by the California Department of Technology In addition, Government Code Section 8592.45
(CDT), and provide options for the Legislature prohibits disclosure of state IS information on
to consider to improve nonreporting entities’ IS critical infrastructure IT systems. This report
compliance to be comparable with reporting complies with state law and the SRL requirement,
entities and achieve a certain IS maturity level. as well as legal and policy guidance from CDT on
publication of the list of nonreporting entities.
BACKGROUND
In this section, we provide definitions for terms we definitions of state agency and state entity within
use throughout the report, specifically nonreporting CDT’s IS authority list specific agencies and types
and reporting entities, and relevant background of entities subject to their authority that is narrower
information across three different topics—IS than the preceding definition of state agency. In the
governance, IS compliance, and IS/IT infrastructure “Major Authorities” appendix on pages 21-23 of the
and staffing. report, we provide more information about these
Definitions of Nonreporting and Reporting statutory definitions as well as other IS-related
Entities. A nonreporting entity is a state entity that authorities that are relevant to this report.
is not under the direct authority of the Governor and,
IS Governance
therefore, generally is considered to be outside of
CDT’s IS authority. In contrast, a reporting entity is Definition of IS Governance. In this report,
we define IS governance as the structure that
under the direct authority of the Governor, is subject
is responsible for the coordination of statewide
to CDT’s IS authority and, therefore, is directed
cybersecurity strategy and development of state IS
by CDT to manage risk and security according
policies, procedures, and standards. Key entities in
to its policies, procedures, and standards.
the state’s IS governance structure that are relevant
The distinction between entities based on their
to this report include the California Cybersecurity
reporting relationship with the Governor comes from
Integration Center (Cal-CSIC) and CDT’s Office of
interpretations of different statutory definitions in
Information Security (OIS). We acknowledge that
CDT’s IS authority—that is, the definition of “state
there are other entities, such as federal entities and
agency” (Government Code Sections 11000 and
industry organizations, involved in IS governance.
11546.1[e][1]) and “state entity” (Government Code
While the focus of our IS governance section is on
Section 11546.1[e][2]). Whereas one definition of
the state’s IS governance structure, we will discuss
state agency applies to all executive branch entities,
other entities’ roles in IS governance as needed in
including nonreporting entities, the two other
the report.
www.lao.ca.gov 5
AN LAO REPORT
Cal-CSIC Provides Statewide IS Leadership. Special Publication (SP) 800-53 as their sources for
Cal-CSIC is the lead entity for coordinating the state’s policies, procedures, and standards. More
statewide IS activities; gathering and disseminating information about the IS sections of SAM and SIMM,
threat intelligence to state entities from the federal FIPS, and NIST SP 800-53 is provided in the “Major
government, county and other local governments, Authorities” appendix on pages 21-23 of the report.
and private companies; and responding to Cal-CSIC and OIS Work Together on
cybersecurity incidents. Cal-CSIC is a partnership Implementation of State’s Multiyear IS Roadmap.
of four state entities: the California Governor’s OIS, in collaboration with other Cal-CSIC partners,
Office of Emergency Services, which administers published the state’s first five-year IS roadmap—
Cal-CSIC; CDT; the California Highway Patrol; and referred to as Cal-Secure—in October 2021. The
the California Military Department (CMD). Figure 1 administration’s intent is for the roadmap to prioritize
provides a graphical representation of Cal-CSIC and reporting entities’ cybersecurity initiatives and
its partners. technical capability investments over the next five
OIS Sets Policies, Procedures, and Standards years. Nonreporting entities also can voluntarily
for Reporting Entities. OIS is responsible for the opt into Cal-Secure implementation. State entities
creation of IS policies, procedures, and standards have begun requesting additional funding and/or
that reporting entities must follow. OIS formalizes positions to acquire capabilities and lead initiatives
IS policies, procedures, and standards in the (as identified by the roadmap). Our understanding
State Administrative Manual (SAM) and Statewide is that there are no reporting requirements specific
Information Management Manual (SIMM). Nearly to Cal-Secure; rather, reporting entities will report
all of the IS sections in SAM and SIMM use Federal to CDT OIS on Cal-Secure progress as part of their
Information Processing Standards (FIPS) and/or routine reporting requirements, and nonreporting
National Institute of Standards and Technology (NIST) entities will not report their progress. More
information about Cal-Secure is
provided in the “Major Authorities”
Figure 1
appendix on pages 21-23 of
the report.
Cal-CSIC Coordinates Statewide IS Activities
Nonreporting Entities’ IS
Governance Varies. Historically,
Education Local
Segments Governments nonreporting entities generally
have not been subject to the
state’s IS governance structure.
CalOES
There have been exceptions,
however. For example, nonreporting
entities are required to submit
Other Executive technology recovery plans for
Branch SOCs CDT Cal-CSIC CHP
critical infrastructure controls and
OIS
information to CDT pursuant to
SOC
Government Code Section 8592.35.
State Entity Also, pursuant to Government Code
IS Programs & Staff CMD
Section 8586.5, some nonreporting
CND
entities are represented within
County Private Cal-CSIC such as the Department
Governments Companies
of Justice. In addition, a number of
nonreporting entities are governed
Cal-CSIC = California Cybersecurity Integration Center; IS = information security; CalOES = California Governor's
Office of Emergency Services; CHP = California Highway Patrol; CMD = California Military Department; CND = Cyber by other federal entities and industry
Network Defense Team; CDT = California Department of Technology; OIS = Office of Information Security; and
SOC = Security Operations Center. organizations and, therefore, are
subject to their specific IS policies,
procedures, and standards.
6 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
Recently Enacted Legislation Provides Some POAM identifies a reporting entity’s deficiencies
IS-Related Requirements for Nonreporting and risks, and explains to OIS how those
Entities and Adds Legislature to State’s deficiencies and risks are being addressed and/or
IS Governance Structure. Chapter 773 of mitigated. Unlike compliance certifications, which
2022 (AB 2135, Irwin) requires nonreporting are annually submitted, OIS requests quarterly
entities to use FIPS 199; FIPS 200; and NIST SP updates on risk registers and POAMs. More
800-53, Revision 5 (and all of their successor information about the relevant SIMM sections
publications) as sources for their IS policies, for compliance certifications and risk registers
procedures, and standards. These sources and POAMs is provided in the “Major Authorities”
largely are the same sources for the IS sections appendix on pages 21-23 of the report.
of SAM and SIMM which contain the policies, Independent Security Assessments (ISAs)
procedures, and standards that reporting entities and IS Program Audits (ISPAs) Used by OIS
must follow. However, unlike reporting entities, to Oversee Reporting Entity Compliance...
nonreporting entities must annually certify their In addition to the annual IS compliance
compliance with legislative leadership. (We documentation, OIS uses two other primary
discuss the compliance certification processes mechanisms to oversee IS compliance: ISAs and
for nonreporting and reporting entities in more ISPAs. ISAs are technical analyses of an entity’s
detail in the “IS Compliance” section immediately cybersecurity defenses that assess whether
below.) Therefore, AB 2135 added the Legislature both networks and systems are configured to
to the state’s IS governance structure specifically prevent attacks. These analyses simulate attacks
for nonreporting entities. More information about to see whether networks and systems can be
AB 2135 and its amendments to Government compromised and data modified and/or stolen.
Code Section 11549.3 is provided in the “Major ISAs of reporting entities typically are performed
Authorities” appendix on pages 21-23 of by CMD, but can be performed by third-party
the report. vendors with OIS approval. ISPAs instead first
review an entity’s IS policies, procedures, and
IS Compliance
standards, and then interview staff and test
Definition of IS Compliance. In this report,
networks and systems to assess whether practice
we define IS compliance as the mechanisms
matches IS requirements under the authorities that
within the IS governance structure that are used
apply to that entity. ISPAs typically are performed
to oversee state entities’ implementation of IS
by OIS.
policies, procedures, and standards, and ensure
…But Frequency of ISPAs Based on OIS’
remediation of assessment and audit findings.
Determination of Reporting Entity’s Risk.
We again acknowledge that there may be other
ISAs are required for all reporting entities every
entities involved in nonreporting entities’ IS
two years (with limited exceptions). However,
compliance, but we focus our IS compliance
CDT cannot perform ISPAs for all reporting
section on the state’s IS compliance requirements.
entities due to a lack of resources. To prioritize
OIS Enforces Reporting Entity IS
ISPAs, OIS uses specific criteria (such as the
Compliance. OIS requires all reporting entities
sensitivity of the data maintained by an entity) to
to submit annual IS compliance documentation.
decide whether reporting entities are high risk.
Two important compliance documents are (1) the
Based on the criteria, OIS currently identifies
IS and privacy program compliance certification,
52 reporting entities as high risk. OIS requires
and (2) the risk register and plan of action and
that high-risk reporting entities complete ISAs
milestones (POAM). A compliance certification
and ISPAs in alternating years. Reporting entities
attests that a reporting entity is compliant with
that are not determined by OIS to be high risk
the policies, procedures, and standards in the IS
can annually certify their IS practice matches
sections of SAM and SIMM. A risk register and
authorities in place of an ISPA (though an ISPA
www.lao.ca.gov 7
AN LAO REPORT
may be requested by OIS at some point). Figure 2 nonreporting entities to certify their compliance
provides a visual representation of these oversight with FIPS 199; FIPS 200; and NIST SP 800-53,
cycles based on OIS’ determination of reporting Revision 5 (and all of their successor publications)
entities’ level of risk. annually to legislative leadership. To certify
Nonreporting Entities’ IS Compliance compliance, nonreporting entities must submit
Requirements Vary. Nonreporting entities largely some of the same IS compliance documentation
are not subject to the state’s IS compliance to legislative leadership as reporting entities
requirements under state law, except as directed submit to CDT—that is, the IS and privacy program
under AB 2135 and discussed in more detail below. compliance certification and the POAM. Unlike
However, as discussed above, nonreporting entities reporting entities, however, nonreporting entities
have been required in the past to submit at least do not need to submit quarterly updates on their
some IS compliance documentation (such as POAMs and the information requested in the POAM
technology recovery plans) to CDT. Nonreporting (an older template) is slightly less comprehensive
entities also might be governed by other federal than in the current POAM used by reporting entities.
entities and industry organizations that require
IS/IT Infrastructure and Staffing
periodic IS assessments and audits, some of which
are similar to state ISAs and ISPAs. Some of the Definition of IS/IT Infrastructure and Staffing.
In this report, we define IS/IT infrastructure and
larger nonreporting entities also might purchase
staffing as the IT processes, services, systems,
cyber insurance coverage, which might require
and staff that support state IS programs. We
entities to undergo periodic IS assessments and
focus on certain processes such as the division of
audits to maintain their policies. Guidance and
IT procurement responsibilities between CDT and
information on cyber insurance providers and their
DGS; certain services and systems such as CDT’s
IS compliance requirements may be provided to
statewide and shared service contracts (that is,
state entities by, for example, the Department
consolidated contracts for IT services managed by
of General Services’ (DGS’) Office of Risk and
CDT and offered to multiple state entities), Security
Insurance Management (OIRM).
Operations Center (SOC), and State Data Center;
AB 2135 Requires Nonreporting Entities
and, certain staff-related issues such as Cal-CSIC
to Submit IS Compliance Documentation
incident response staff, IT staff classifications,
to Legislature. Assembly Bill 2135 requires
and IS staff recruitment and
training efforts.
Figure 2 Cal-CSIC Staff Provides
Statewide Incident Response.
Reporting Entity IS Oversight Cycles
Cal-CSIC staff support IS and IT
staff at state entities (along with
other entities statewide) to respond
Year 1 ISA
Year 1
ISA
Year
2
IS
t
b
s
o
u
r e
b
c
a
m
y
c
b
i
h
t
e
e
r
r
e
s
s
e
.
q
c
S
u
u
e
ta
r
s
i
t
t
t
e
s
y
e
i
f
n
o
n
c
r
t i
i
a
t
d
i
s
e
e
s
s
n
i
t
s
a
s
t
l
a
s
a
n
o
n
c
d
c
e
a
d
t
n
o
a ta
P
A
Cal-CSIC if there are attacks and/or
High-Risk
Reporting Entity Cycle threats identified by entities’ IS and
Reporting Entity Cycle
Year
4 C
I
le
T
v
s
e
t
l
a
o
ff
f
t
r
h
e
a
s
t
p
n
o
e
n
e
s
d
e f
r
r
e
o
m
m
e d
C
i
a
a
l
t
-
io
C
n
S
.
I C
Th e
h
Year
2 Compliance
Certification
eck-In
ISPA Year 3
IS
A s
o
a
t
n
f
a
d
t
f
h
f
o
e
v
n
a
d
r
t
a
i
h
e
t
e
a
s
o
b
b
t
r
a
h
e
s
e
a
e
r
c
d
h
IS
o
a
n
r
n
e
d
t
s
h
/
o
o
e
u
r
s
r
i
c
e
n
e
v
c
s
e
id
ri
e
ty
n t,
available to the state entity. For
IS = Information Security; ISA = independent security assessment; and ISPA = information security
program audit. example, Cal-CSIC might respond
to a serious data breach and/or
8 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
incident with the whole of its incident response Shared IT Procurement Process
team and request that additional IS and IT staff, as Responsibilities Between CDT and DGS. Public
well as subject matter experts, from the affected Contract Code Sections 12100-12113 divide state
entity also respond. Lower-severity data breaches IT procurement process responsibilities between
and/or incidents might only require a few Cal-CSIC CDT and DGS. CDT is responsible for contracts
staff, and rely more on internal entity IS and IT staff for IT goods and services related to IT projects
for incident response and remediation efforts. (that is, a set of activities required to plan,
CDT Operates the State SOC and State develop, and implement an IT system) as well as
Data Center. CDT operates the state SOC, which telecommunications goods and services, while DGS
continuously monitors and reacts to threats on the is responsible for contracts for all other IT goods and
California Government Enterprise Network (CGEN), services (such as the replacement of computers,
the state government’s primary enterprise network. mobile devices, and other hardware). Authority
Many reporting entities connect to CGEN, which over state IT procurement policy and procedures
allows CDT’s SOC to identify and respond more also is divided between CDT and DGS based on
quickly to attacks and/or threats to these entities. their separate responsibilities. More information
CDT’s SOC also transmits any information about on Public Contract Code Sections 12100-12113
attacks and/or threats to Cal-CSIC to determine is provided in the “Major Authorities” appendix on
if, for example, education segments, other pages 21-23 of the report.
government entities, and/or private companies are State Entities Hire IS and IT Staff Using
responding to similar attacks and/or threats. CDT Consolidated IT Classifications Approved in
also maintains the State Data Center, which hosts a 2018. In 2018, the State Personnel Board approved
number of state entities’ IT infrastructure (including the consolidation of 36 IT classifications into nine
some of the nonreporting entities’ applications and new classifications to be used to hire both IS and
systems) and monitors it for attacks and/or threats. IT staff across state entities. Six IS and IT functional
CDT Also Procures and Manages Statewide areas are used to further specify workload for these
and Shared Service Contracts, Including for IS. positions, including IS engineering and system
CDT also procures and manages both statewide engineering, but there are no IT classifications
and shared service contracts for state entities, specific to IS.
including a small number of IS-related contracts. State Engaged in Number of Efforts to
Statewide contracts managed by CDT allow Recruit and Train IS Staff. Cal-CSIC and CDT—
vendor-hosted subscription services—IT services in collaboration with the California Department
provided and primarily supported by private of Human Resources (CalHR), the Government
vendors—used by most state entities to be provided Operations Agency (GovOps), and other state
to all entities at a lower cost than they might entities—have set up several programs to
be able to negotiate with vendors as individual recruit and train IS staff to work in state entities.
entities. One example of a statewide contract is For example, the IT Cybersecurity Non-Traditional
the state’s Microsoft 365 contract. Shared service Apprenticeship Program began in September 2021
contracts managed by CDT also allow for certain to train current non-IS state staff for up to two years
IT services to be provided, but typically are for a to qualify for IS staff positions. Also, the Work for
smaller number of state entities using a specific California campaign launched in 2023 specifically
type of service to reduce their current expenditures recruits recently laid off IS and IT workers at private
on similar services. One example of a shared companies on behalf of state entities. State entities
service contract is security information and event also recruit from colleges and universities and, in
management software that provides a group of some cases, set up programs in collaboration with
state entities with several capabilities prioritized in colleges and universities to recruit and train future
Cal-Secure. IS and IT staff for state entities. Finally, CDT’s Office
of Professional Development and Training Center
works with the department’s OIS on centralized and
subscription-based IS training.
www.lao.ca.gov 9
AN LAO REPORT
Nonreporting Entities’ IS/IT Infrastructure Center, and use services provided through both
and Staff Varies. Generally, unlike reporting statewide and shared service contracts procured
entities, nonreporting entities are not required to and managed by CDT. Other nonreporting entities,
use specific IS/IT infrastructure and staff under however, maintain their own IS and IT infrastructure
state law. A number of nonreporting entities choose to meet industry- or program area-specific needs
to use CDT’s SOC, host at least some of their and/or to ensure their independence from entities
IT applications and systems on the State Data under the direct authority of the Governor.
ASSESSMENT OF NONREPORTING
ENTITIES’ IS COMPLIANCE
The first portion of this section lays out our for state entities. We also held meetings with the
research methodology. We then discuss how Department of Finance (DOF) to discuss their
nonreporting entities are defined for the purposes analysis of IS-related budget proposals from
of this report and recent effects of AB 2135 on nonreporting entities.
IS programs. Lastly, we provide our evaluation of Review of Nonreporting Entities’ IS
nonreporting entities’ IS programs. Documentation. Our office requested IS governance
and compliance documentation from nonreporting
RESEARCH METHODOLOGY entities in advance of the interviews. Some examples
Interviews With Nonreporting Entities’ of the documentation we requested included a list of
IS Programs. Our office conducted a total of the IS assessments and audits performed over the
34 one-hour interviews, primarily with staff of last five years; all of their IS policies, procedures, and
nonreporting entities’ IS programs. We asked a standards; and recent IS and IT budgets with position
standardized set of interview questions about IS information. We reviewed this documentation to
governance, IS compliance, and IS/IT infrastructure inform our questions during the interviews and our
and staffing to code nonreporting entities’ analysis in this report. Any confidential information
responses. Out of the 22 entities we identified as that was contained in this documentation was
nonreporting entities (which we provide later in maintained in a manner consistent with the relevant
the report), our office interviewed 17 nonreporting Government Code sections and SRL requirement
entities. We did not interview some of the remaining described in the “Introduction” section.
five entities primarily because these were entities Review of Federal and State IS Authorities
where their IT infrastructure is hosted by other and Literature. We reviewed federal and state IS
entities (some of which we interviewed) or they have policies, procedures, and standards, including those
no IT infrastructure. A few entities, however, did not in the “Major Authorities” appendix. We also reviewed
respond to our requests for an interview. We also available literature on specific topics related to the
scheduled an additional 12 interviews with reporting report, such as specific compliance requirements in
entities and entities outside of the executive branch. certain critical infrastructure sectors.
Meetings With Entities in State’s IS
Identification of Nonreporting Entities
Governance Structure. Our office also held
several meetings with Cal-CSIC, OIS, and CMD. One Statutory Interpretation Used in Report to
We discussed a number of topics including possible Create Nonreporting Entities List… In consultation
with CDT, we created a list of nonreporting entities
definitions for nonreporting entities (including the one
based on one possible interpretation of state statute.
used for the nonreporting entities list in this report),
First, we identified entities based on the broad
their understanding of nonreporting entities’ IS
definition of state agency in Government Code
governance and compliance activities, and their
Section 11000. (There are narrower definitions in
IS/IT infrastructure and staff training offerings
10 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
other code provisions.) Then, we identified which of In contrast, CDT identified some of the entities on the
those entities are not under the direct authority of list as “voluntarily complying” with state IS policies,
the Governor and, therefore, would not be defined procedures, and standards. We kept these entities
as state entities under Government Code Section on the list because of potential noncompliance in
11546.1(e)(2). Our determination as to the reporting the future. We acknowledge alternative approaches
relationship with the Governor required, for example, would result in differences with our list. As we
a review of the constitutional and statutory authorities describe below, we recommend the Legislature
governing these entities. This list is provided below in amend statute to clarify both the definitions and use
Figure 3 as the list of nonreporting entities requested of state agency and state entity in order to clarify
in the SRL. The publication of this list conforms with CDT’s IS authority.
legal and policy guidance from CDT.
…But Other Statutory Interpretations Could IMPACTS OF AB 2135
Change List of Nonreporting Entities. The list of ON IS PROGRAMS
nonreporting entities in this report is based on one
AB 2135 Requires Nonreporting Entities to
statutory interpretation used to identify entities that
Follow Federal IS Authorities and Undergo
are not under the direct authority of the Governor
ISAs Much Like Reporting Entities. Assembly
and, therefore, generally are considered to be
Bill 2135 requires nonreporting entities to use
outside of CDT’s IS authority. This list is not definitive
certain FIPS and NIST SP 800-53, Revision 5 (and
or exhaustive. For example, we removed those
all of their successor publications) as sources
entities for which we could not determine the exact
for their IS policies, procedures, and standards.
reporting relationship with the Governor (such as
These sources largely are the same sources for the
independent entities in statute that are organized
IS sections of SAM and SIMM which contain the
under state agencies identified in Government Code
policies, procedures, and standards that reporting
Section 11546.1[e][1] in order to focus solely on those
entities must follow. Assembly Bill 2135 also requires
nonreporting entities clearly covered by the SRL.
nonreporting entities to certify compliance with
their IS policies, procedures, and standards to
Figure 3 legislative leadership annually. To certify compliance,
nonreporting entities must submit some of the
Nonreporting Entities Based on One
same IS compliance documentation to legislative
Statutory Interpretation
leadership as reporting entities submit to CDT—
Board of Equalization that is, the IS and privacy program compliance
Citizens Compensation Commission certification and the POAM.
Commission on Peace Officer Standards and Training
AB 2135 Addresses Some Governance and
Commission on State Mandates
Department of Education (Superintendent of Public Instruction) Compliance Issues That SRL Asked Us to
Department of Insurance (Insurance Commissioner) Consider. The SRL asked our office to consider
Department of Justice (Attorney General)
whether some of the nonreporting entities could
Education Audit Appeals Panel
benefit from compliance with and reporting on IS
Gambling Control Commission
Health Benefit Exchange (Covered California) policies and procedures similar to those set by CDT,
Little Hoover Commission and to provide options for the Legislature to consider
Office of Tax Appeals
to improve nonreporting entities’ compliance to
Office of the Inspector General
be comparable with reporting entities and achieve
Office of the Lieutenant Governor
Privacy Protection Agency a certain IS maturity level. (An entity’s IS maturity
Public Utilities Commission level is how prepared state entities’ IS programs are
Secretary of State
to prevent and/or respond to a cyberattack
State Auditor
and/or threat.) We find that some of the governance
State Controller
State Lottery and compliance issues raised in the SRL are
State Treasurer addressed by AB 2135. For example, federal IS
Summer School for the Arts
authorities that nonreporting entities must follow
www.lao.ca.gov 11
AN LAO REPORT
under AB 2135 are similar to those set by CDT, Remainder of Assessment and Options
and the reporting on their compliance with those Consider Other Issues Affecting Nonreporting
authorities to legislative leadership is similar to Entities’ Compliance and Maturity. Therefore, in
what is required by CDT (with the exception of light of AB 2135, the remainder of our assessment
annual POAM updates to the Legislature instead focuses on the results of our research on
of quarterly updates required by CDT for reporting nonreporting entities’ IS programs across the topics
entities). Also, the biennial ISAs required by AB 2135 of IS compliance, IS governance, and
for nonreporting entities are completed by CMD IS/IT infrastructure and staffing. Similarly, the
or third-party vendors in much the same way as options we provide in our report focus on issues
for reporting entities, thereby helping nonreporting and needs identified in our research that have not
entities to improve their IS compliance and increase already been addressed in AB 2135, but could
their IS maturity level. Figure 4 shows how specific improve nonreporting entities’ IS compliance
IS compliance requirements for nonreporting and maturity.
and reporting entities compare after enactment
of AB 2135. EVALUATION OF NONREPORTING
Assembly Bill 2135, when fully implemented, ENTITIES’ IS PROGRAMS
likely will provide increased oversight of
To protect the confidentiality of the information
nonreporting entities that, while not required by
received from nonreporting entities through our
state law to follow IS requirements set by OIS,
documentation review and interviews, we use
are state government entities largely funded with
descriptive language to summarize our review
appropriations approved by the Legislature. We
and their responses rather than naming entities
find it is important, therefore, that these entities
and providing the number of responses from
be subject to some of the same accountability
nonreporting entities that apply to each finding.
for and governance of their IS programs as
reporting entities.
Figure 4
Comparison of Entities’ Specific IS Compliance Requirements After
Enactment of AB 2135a
IS Compliance Requirement Reporting Entities Nonreporting Entitiesb
Primary Governing Statutory SAM and SIMM sections 5300 (largely using FIPS 199, FIPS 200, and NIST SP 800-53.
Authoritiesc FIPS and NIST SP 800-53 as the sources for Nonreporting entities also may choose to
their policies, procedures, and standards). voluntarily adopt reporting entities’ primary
governing statutory authorities.
Assessments and Audits Biennial ISAs by CMD, and biennial ISPAs for Biennial ISAs and as-needed ISPAs from
high-risk reporting entities. ISAs also can be CDT. ISAs may be completed by CMD or a
completed by a third-party vendor, if approved third-party vendor.
by CDT.
Compliance Certification and Submission of annual compliance certifications Submission of annual compliance certifications
Reporting and other IS compliance documentation (such and POAMs to legislative leadership.
as POAMs) to CDT. POAMs must be updated
quarterly.
a Chapter 773 of 2022 (AB 2135, Irwin).
b Nonreporting entities subject to these requirements might depend on which statutory interpretation is used for the definitions of “state agency” and “state
entity” in CDT’s IS authority.
c For more information on the governing statutory authorities we reference in this figure, please refer to the “Major Authorities” appendix at the end of the
report.
IS = information security; SAM = State Administrative Manual; SIMM = Statewide Information Management Manual; FIPS = Federal Information Processing
Standards; NIST = National Institute for Standards and Technology; SP = Special Publication; ISAs = independent security assessments; CMD = California
Military Department; ISPAs = information security program audits; CDT = California Department of Technology; and POAM = plan of action and milestones.
12 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
IS Governance This figure shows that while some nonreporting
entities receive hundreds of millions of dollars
Significant Differences in Nonreporting
and employ thousands of staff, others receive
Entity Functions, Roles, and Size. The term
millions of dollars or less and employ few (if any)
nonreporting entity might be useful when
staff. Furthermore, the roles of some entities (for
considering whether or not an entity is considered
example, some of the constitutional officers) are
to be outside of CDT’s IS authority but the term
critical to the performance of certain state functions
does not identify the relative risk for these entities.
(for example, accounting and cash management)
Moreover, in light of AB 2135, the term is less
whereas other entities, while serving important
helpful when considering if there are benefits from
oversight functions, do not perform central state
additional compliance and reporting requirements
functions and roles. Therefore, the findings and
or other resources to improve such an entity’s IS
options in this report generally cannot be applied
compliance and maturity. There are significant
across all nonreporting entities. In many cases,
differences, for example, in the types of programs
our findings and options are specific to a subset
and services each nonreporting entity provides, in
of nonreporting entities based on their functions,
the roles they serve on behalf of the state, and in
roles, and size.
the size of their budgets and staff. To illustrate these
differences in terms of the latter, Figure 5 provides Majority of Nonreporting Entities Cited State
the total fund budgets and number of positions IS Policies, Procedures, and Standards as
approved for these entities in the 2022-23 Budget Primary Framework for IS Programs. A majority
Act, sorted from largest to smallest budgets. of the nonreporting entities we interviewed either
provided documentation showing, or confirmed
in their responses, that SAM
Figure 5 and SIMM Sections 5300 as
well as NIST SP 800-53 are the
Budgets and Positions at Nonreporting Entities in
principal authorities for their own
2022-23 Budget Act
IS policies, procedures, and
Total Funds
standards. If these were not their
Nonreporting Entities (in Thousands) Positions
principal authorities because,
Public Utilities Commission $1,889,094 1,501
for example, they adopted other
Department of Justice (Attorney General) 1,166,144 5,791
federal or industry IS authorities
State Lottery 1,110,199 1,080
Health Benefit Exchange (Covered California) 759,469 1,465 as their primary framework, some
State Controller 361,530 1,591 entities still cross-referenced
Department of Insurance (Insurance Commissioner) 325,698 1,400
the policies, procedures, and
Gambling Control Commission 154,717 40
Secretary of State 152,396 592 standards they adopted with
Department of Education (Superintendent of Public 110,267 2,566 SAM and SIMM Sections 5300
Instruction)
and/or NIST SP 800-53. Some
Commission on Peace Officer Standards and 110,166 263
nonreporting entities were required
Training
Commission on State Mandates 71,876 17 to adopt other authorities specific
State Auditor 46,752 217 to their programs and services
State Treasurer 46,360 252
that, in many cases, were more
Office of the Inspector General 42,275 214
Board of Equalization 32,563 194 prescriptive than state authorities.
Office of Tax Appeals 27,138 117 Many nonreporting entities also
Privacy Protection Agency 10,000 34 cited Cal-Secure as guiding their
Summer School for the Arts 4,273 4
cybersecurity initiatives and
Office of the Lieutenant Governor 2,708 15
Little Hoover Commission 1,292 7 technical capability investments.
Education Audit Appeals Panel 1,177 5 Altogether, these findings indicate
Citizens Compensation Commission 10 — nonreporting entities’ significant
adoption and awareness of
state IS policies, procedures,
and standards.
www.lao.ca.gov 13
AN LAO REPORT
Many Nonreporting Entities Receive and and standards to be too expensive and/or too
Use Threat Intelligence Information From limited given their constrained IS budgets. In sum,
Cal-CSIC… Many of the nonreporting entities while a majority of nonreporting entities adopt
we interviewed mentioned that they receive and and/or are aware of state IS policies, procedures,
use threat intelligence information from Cal-CSIC and standards, many of these entities struggle
to, for example, block malicious Internet Protocol to implement them based on current supporting
addresses—that is, unique identifiers associated materials from CDT.
with internet or network devices engaged in Some Entities Said Statutory Ambiguity
hacking attempts or spamming activities— Impacted IS Program Decision-Making. Some
and monitor their networks for known threat entities we interviewed were not able to provide
actors—that is, organizations or people known to definitive answers to our questions about their
engage in cyberattacks. Therefore, even though reporting relationship with the Governor and,
nonreporting entities are not governed by the thus, were unsure if they were nonreporting
state’s IS governance system, many of them are entities. Some of them had communicated with
taking advantage of resources from the state’s IS Cal-CSIC and CDT to clarify whether or not they
governance entities. are nonreporting entities, but a number of them
…But Only Some Sought Cal-CSIC and CDT’s told us they were unable to resolve this uncertainty.
Guidance on Cal-Secure Implementation. Some said the ambiguity in statute about their
Although many nonreporting entities cited status made their decisions on IS governance and,
Cal-Secure as one of the frameworks guiding their by extension, compliance more difficult. We find
cybersecurity initiatives and technical capability the inability of some entities to determine whether
implementations, only some of them said in their or not they are nonreporting entities because of the
interviews that they actively sought guidance from ambiguities in CDT’s IS authority to be problematic
Cal-CSIC and CDT on Cal-Secure. Some of the as it leaves oversight of these entities in limbo.
entities may not have included their consultation Furthermore, it could affect the implementation
with Cal-CSIC and CDT in their responses to us, of AB 2135, limiting the accountability for
but to some degree, nonreporting entities may be and governance of state government entities
using Cal-Secure without much guidance from largely funded with appropriations approved by
Cal-CSIC and CDT to inform their implementation of the Legislature.
the roadmap.
IS Compliance
Many Nonreporting Entities Found CDT’s
Nearly All Nonreporting Entities Underwent
IS Resources Difficult to Use. A majority of
an ISA in the Past Several Years. According to
the nonreporting entities that use SAM and
our documentation review, and verified by entities’
SIMM Sections 5300 and/or NIST SP 800-53 as
responses to our interview questions, we found
principal authorities for their IS programs said
that nearly all nonreporting entities underwent
they found implementation of the framework to
an ISA in the past two to three years. Some of
be difficult because guidance, information, and
the nonreporting entities did wait several years
templates made available by CDT were hard to
between ISAs, citing difficulty obtaining funding
understand and not necessarily relevant to their
for an ISA every two years. However, for larger
program areas. We understand from CDT that
nonreporting entities, biennial ISAs were only one
some of the guidance, information, and templates
of several IS assessments and audits undertaken,
are intentionally general to allow a wider range of
some of which were required by federal authorities,
state entities to use them, but some nonreporting
industry organizations, and some cyber insurance
entities considered the lack of specificity in CDT’s
providers. A number of nonreporting entities
documentation to be problematic. A number
cited AB 2135, as of 2022, as a reason for their
of nonreporting entities also found CDT’s
decision to undergo an ISA. Consistent with
recommendations on hardware, software, and/or
CDT’s requirement that reporting entities undergo
tools to implement state IS policies, procedures,
14 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
ISAs once every two years (with some limited Some Nonreporting Entities Required to
exceptions), nonreporting entities appear to be Perform Additional IS Compliance Activities by
undergoing ISAs at a comparable rate consistent Cyber Insurance Providers. Some nonreporting
with the intent of AB 2135. entities we interviewed said several of their IS
Some Nonreporting Entities Voluntarily compliance activities were required by their cyber
Comply With State IS Policies, Procedures, insurance providers to maintain their policies,
and Standards. As mentioned earlier, some including certain IS assessments and audits like
nonreporting entities voluntarily choose to ISAs. A small number mentioned they had to adopt
comply with state IS policies, procedures, and certain IS policies, procedures, and standards as
standards. Voluntary compliance means these well, and certify their compliance with particular
entities undergo ISAs and ISPAs (if deemed high requirements that were set by their cyber insurance
risk) and submit IS compliance documentation to providers. While cyber insurance providers are not
OIS just as reporting entities do. However, unlike a formal part of the state’s IS governance structure,
reporting entities, nonreporting entities can choose it appears that, at least for some nonreporting
to stop their compliance with state IS policies, entities, cyber insurance providers play a key
procedures, and standards at any time. None of role in their decisions to engage in certain IS
the nonreporting entities we interviewed indicated compliance activities.
they would stop their voluntary compliance. Some Some Nonreporting Entities Identified
did mention, however, that they decided internally the Lack of Certification and Education
to fully adopt some state policies and standards Opportunities for Existing Staff to Improve
but modify others because, for example, their Compliance. Some nonreporting entities were
alternative approach to implementation was unaware of how to achieve compliance with state IS
not explicitly allowed or their budgets could not policies, procedures, and standards, and requested
cover full implementation of a state policy or that CDT provide certification and education
standard. Therefore, voluntary compliance shows opportunities to help existing IS and IT staff learn
nonreporting entities’ willingness to follow state IS how to improve their compliance efforts and train
policies, procedures, and standards, but does not others. A small number of entities sought external
guarantee full compliance. training on some authorities that inform the state’s
Some Nonreporting Entities in Voluntary framework (for example, NIST SP 800-53) to
Compliance Cited a Lack of Documentation help them with state IS compliance activities, but
Review by CDT. A small number of nonreporting said external training was not always tailored to
entities that are in voluntary compliance with state state IS policies, procedures, and standards. We
IS policies, procedures, and standards submitted identify other staff training-related findings from
IS compliance documentation with CDT, but our research under the “IS/IT Infrastructure and
received little to no feedback on their submissions. Staffing” topic in the next section, but found the
These entities said the lack of response from CDT request for official certification of compliance
made it difficult to, for example, determine whether knowledge from CDT to be noteworthy.
deficiencies identified in ISAs had been addressed
IS/IT Infrastructure and Staffing
consistent with state authorities and guidance.
Several Nonreporting Entities Use CDT
As a result, some of these entities might not be
IS and IT Service Offerings... According to
able to verify that their IS compliance and maturity
CDT, several nonreporting entities use some
is improving due to a lack of responsiveness from
combination of the department’s SOC and State
CDT. If some nonreporting entities decide in the
Data Center IT services. Some entities connect
future to consider voluntary compliance with state
to CGEN, for example, and/or host specific
IS requirements, this lack of response also might
applications and/or systems on the State Data
discourage them from agreeing to continue with
Center. Other nonreporting entities decided on
voluntary compliance.
more novel approaches to working with CDT’s SOC.
www.lao.ca.gov 15
AN LAO REPORT
For example, at least one nonreporting entity IS compliance and maturity, but also repeatedly
directed a portion of its network traffic to the mentioned a lack of qualified IS staff as one
department’s SOC, while maintaining their own of the barriers to further improvement of their
separate entity SOC for internal network traffic. IS programs.
We understand from CDT that nonreporting Several nonreporting entities also mentioned
entities’ use of its SOC and State Data Center gives lower wages for state IS staff relative to the private
the department more visibility into nonreporting sector, and some entities described the current
entities’ IS activities and, consequently, allows CDT IT staff classifications as too broad (even with the
to help these entities improve their IS compliance more specific functional areas like IS engineering)
and maturity. to attract staff with the proper qualifications and
…But Some Nonreporting Entities Said work experience. CalHR’s 2021 California State
Private Vendors Offered Better Levels of Employee Total Compensation Report shows
Service and Pricing for IS and IT Services. average turnover and vacancy rates for entry-level
While some nonreporting entities cited an interest IT specialist staff are comparable to rates for
in CDT’s SOC and State Data Center IT service other state staff. However, wages for entry-level
offerings, these entities decided that their contracts IT specialist staff are at least 20 percent lower
with private vendors offered comparable or better relative to the private sector in March 2021. Total
levels of service and pricing. While we were not compensation, including health care and retirement
able to compare service contracts and rates in our benefits, appears to be more comparable between
research, it seems at least possible based on our private sector companies and state government,
assessment of certain budget proposals related however. Consequently, whether recruiting and
to the State Data Center that rates for some IT retaining IS professionals is more challenging than
services offered by CDT are not competitive with other state positions (at least for entry-level IT
private vendor rates. specialist staff) is somewhat unclear. However, since
Nearly All Nonreporting Entities Cited March 2021, when these data were collected and
Significant Challenges Hiring, Training, and published, the state’s labor market has improved
Retaining IS Staff. In nearly every one of our dramatically, making it more difficult to attract
interviews with nonreporting entities, entities and retain qualified IS staff. Nationally, businesses
expressed difficulty recruiting, training, and and governments today are only able to fill about
retaining IS staff. Several entities described their half of the needed technology job openings,
efforts to improve staff recruitment, training, and whereas they could regularly fill most positions
retention, but these efforts achieved mixed results. prior to the pandemic. At the same time, the state’s
Some examples of these efforts included the unemployment rate has decreased from 8.4 percent
aforementioned IT Cybersecurity Non-Traditional to 4.3 percent (as of February 2023). Moreover,
Apprenticeship Program, similar internal entity inflation has increased at rates notably higher than
apprenticeships to retrain existing staff into IS staff, recent state salary adjustments. Of the issues
college outreach to create pipelines from IS-related identified across the three topics in this report, we
degree programs into nonreporting entity IS offices, find that IS staff-related issues might be some of the
and internship and student assistant programs. most important to address if nonreporting entities
(and state entities in general) are to improve their IS
Many nonreporting entities used cybersecurity
compliance and maturity.
training software offerings to conduct at least
annual cybersecurity awareness training and Smaller Nonreporting Entities Raised
perform mock phishing exercises—that is, e-mails Concerns About Procurement Delays. Some of
or messages sent by internal IS staff to attempt to the smaller nonreporting entities we interviewed
mislead an entity’s employees into, for example, raised issues with the division of IT procurement
clicking a link or downloading a file that contains responsibilities between CDT and DGS pursuant to
malware. Nonreporting entities cited the success Public Contract Code Sections 12100-12113. This
of these efforts as one reason for their increased includes procurement of IT goods and services
16 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
that are needed to remediate deficiencies and entities said they did not have enough staff to
weaknesses identified through, for example, ISAs dedicate to procurements for IT goods and
and ISPAs. These entities cited DGS’s lack of services, which can take months or in some
IT expertise as one barrier to more expeditious cases years, and instead sought improvements to
procurement of IT goods and services, as streamline IT procurement processes (particularly
well as unnecessarily low dollar thresholds for smaller purchases).
for routine purchases. A small number of these
OPTIONS TO IMPROVE NONREPORTING
ENTITIES’ IS COMPLIANCE AND MATURITY
Consistent with the requirements of the SRL, we 11549-11549.4 (OIS) and other statutes that
provide options for legislative consideration in this cross-reference CDT’s IS authority. In addition, the
section that could improve nonreporting entities’ IS Legislature could consider whether to direct CDT to
compliance to be at least comparable to reporting provide accompanying legal and policy guidance to
entities and to achieve a certain IS maturity level. any state entity affected by the statutory changes to
We present these options to the Legislature based confirm whether or not they are now subject to the
on our assessment of their benefit to nonreporting state’s IS governance structure. We emphasize this
entities’ IS compliance, in order from highest to option as one potential solution to the question of
lowest emphasis and impact. However, as we whether or not an entity is reporting or nonreporting
discussed in our assessment, there are significant and to any statutory interpretations that lead to
differences in the types of programs and services inconsistencies in the implementation of the state’s
each of the nonreporting entities provide, the roles cybersecurity efforts and strategy.
they serve on behalf of the state, and the size of Recommend Monitoring Nonreporting
their budgets and staff. Therefore, while we do Entities’ Compliance With and Implementation
generally emphasize options that could benefit all of AB 2135. We recommend monitoring
nonreporting entities, we also offer options that nonreporting entities’ compliance with and
might benefit only some subset of nonreporting implementation of AB 2135. Assembly Bill 2135
entities. As with our assessment, we organize added the Legislature to the state’s IS governance
our options across the topics of IS governance, structure. How legislative leadership (and
IS compliance, and IS/IT infrastructure and staffing. any other Members and legislative staff) use
the IS compliance documentation submitted
IS Governance
by nonreporting entities to assess whether
Consider Amending CDT’s IS Authority to
nonreporting entities are indeed in compliance
Address Statutory Ambiguity of State Agency
could be critical to the longer-term success of
and State Entity Definitions and Use. One
the law. For example, implementation of AB 2135
option for legislative consideration to improve IS
may require analysis of the IS compliance
governance of nonreporting entities is to amend
documentation to determine whether nonreporting
CDT’s IS authority to address the current ambiguity
entities are making progress in remediating some
in the definitions and use of state agency and state
of their identified deficiencies and weaknesses.
entity, and make clear whether state entities are
This analysis, depending on how it is performed,
nonreporting or reporting. Amendments to this
could require additional legislative resources
authority would include changes to the relevant
and expertise or further clarification of the
paragraphs in Government Code Section 11546.1,
responsibilities of legislative leadership (and others)
but also to other sections of the department’s
in statute.
authority such as Government Code Sections
www.lao.ca.gov 17
AN LAO REPORT
Consider Directing CDT to Improve Ease of provisional budget bill language for nonreporting
Use of IS-Related Guidance, Information, and entities’ IS-related budget requests to condition
Templates. One other option for the Legislature the expenditure of funding on compliance with
to consider to improve IS governance is to certain IS policies, procedures, and standards.
direct CDT to make their IS-related guidance, For example, nonreporting entities are requesting
information, and templates both simpler and more funding to implement some of the cybersecurity
specific to different program areas. Materials initiatives and technical capabilities in Cal-Secure.
that are difficult to understand and use could The administration could evaluate whether
be one potential barrier to more adoption of and demonstrated progress towards implementation of
compliance with state IS policies, procedures, and these capabilities and initiatives as a requirement
standards by nonreporting entities. For example, to receive some amount of additional funding might
materials could provide clearer guidance on how benefit statewide efforts to improve IS compliance
to prioritize existing funding, staff, and time if new and maturity.
requirements are implemented without additional The Legislature also might consider whether
funding or positions. Also, CDT could consider its monitoring of AB 2135 compliance and
providing guidance to state entities on how long it implementation could be used to inform its analysis
will take to hear back from them on their reviews of budget requests. For example, if deficiencies or
of compliance documents and, if state entities weaknesses are identified in nonreporting entities’
have not heard back, provide the relevant contact POAMs, the Legislature might condition funding
information to address the issue. This guidance on their remediation and request more frequent
would help, for example, nonreporting entities in updates on their POAMs. The coordination of this
voluntary compliance with state requirements better analysis by the Legislature across different program
understand the documentation review process. areas during the budget process also might warrant
Furthermore, CDT could consider providing more consideration of internal organizational changes
varied recommendations on hardware, software, to facilitate broader IS discussions (for example,
and tools with different levels of service and prices the creation of a new budget subcommittee
to accommodate the wide range of nonreporting focused on these and other capital outlay and IT
entity budgets. issues). We emphasize these options as important
Consider Directing Cal-CSIC to Increase opportunities for the administration and the
Outreach to Nonreporting Entities Implementing Legislature to obtain additional information through
Cal-Secure. Another option for the Legislature the budget process about nonreporting entities’ IS
to consider is to direct Cal-CSIC to increase its compliance and to guide the development of their
outreach to nonreporting entities known to be IS programs.
implementing Cal-Secure to actively offer guidance Consider Directing Cal-CSIC and CDT
on the implementation. Cal-CSIC could work with to Report to the Legislature on Cal-Secure
CDT and DOF to identify nonreporting entities that Implementation. Another option the Legislature
are requesting funding and positions to implement could consider, consistent with a recent
Cal-Secure, and coordinate meetings and/or recommendation of our office on IS proposals
workshops for these entities to ask Cal-CSIC in the Governor’s 2023-24 budget, is to direct
questions about the cybersecurity initiatives and Cal-CSIC (in consultation with its partners) to report
technical capabilities in the roadmap. annually to the Legislature on the implementation
of Cal-Secure initiatives and technical capabilities.
IS Compliance
This option could improve the Legislature’s
Consider Opportunities to Condition State
oversight of Cal-Secure implementation, including
Funding on Compliance With Federal and State
nonreporting entities’ efforts using funding and/or
IS Policies, Procedures, and Standards. One
positions approved through the budget process.
option the Legislature could consider is to request
that Cal-CSIC, CDT, and DOF evaluate the use of
18 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
Consider Requiring CDT to Develop (Government Code Section 11546.45(a)(4) requires
Centralized IS Training Hub for IS Compliance CDT to implement a plan to establish centralized
Certification and Education. The Legislature contracts for at least some shared services,
also might consider requiring CDT to develop a including IS services.) The Legislature also could
centralized IS certification and training hub that consider amending current reporting requirements
helps educate and certify all state entity IS staff in statute to require that CDT identify any shared
on current and forthcoming state IS policies, services assessed, procured, and advertised to
procedures, and standards. This centralized IS state entities in its annual report. Shared IS service
training hub could build on current IS training contracts available to state entities at a lower cost
programs led by CDT’s Office of Professional may incentivize additional nonreporting entities to
Development and Training Center, but also focus use these services, which could provide CDT with
on certification of compliance knowledge so that IS increased visibility into those entities’ IS programs.
staff across state entities could easily demonstrate Consider Directing Administration to
their understanding of federal and state IS policies, Expand on Existing Recruitment, Training,
procedures, and standards. The Legislature also and Retention Efforts to Increase Size of IS
might consider whether specific measurable goals Workforce. One other option the Legislature
or outcomes for training efforts through this hub, could consider is to direct Cal-CSIC, CalHR, CDT,
including the number of staff from nonreporting GovOps, and other relevant state agencies and
entities that were trained, might help it monitor entities to consider expanding their existing efforts
CDT’s progress in this area. to recruit, train, and retain IS staff. The Legislature
Consider Requiring an Evaluation of Major could consider whether to direct these agencies
Cyber Insurance Products to Understand and entities to evaluate the effectiveness of existing
Compliance Requirements. One other option efforts based on, for example, the number of new
the Legislature could consider is to request that IS staff recruited, trained, and/or retained and
DGS’s OIRM, in consultation with CDT, provide an report back to the Legislature with a plan on how to
evaluation of the major cyber insurance products expand and/or improve these efforts.
currently available to state entities to determine The Legislature also could consider whether
which products have IS compliance requirements to expand the scope of the evaluation to include
that might improve the IS compliance and maturity considerations of employee compensation, IT staff
of nonreporting entities. The Legislature also classifications, and other human resources-related
might consider directing DGS, in consultation topics that might affect the ability of the state to
with CDT and other relevant state departments recruit and retain IS staff. These employees are
such as the Department of Insurance, to develop represented at the bargaining table by Service
criteria to recommend cyber insurance products Employees International Union, Local 1000.
to state entities that incorporate as one of the The state’s labor agreement with Local 1000 is
goals improved IS compliance and maturity for scheduled to expire June 30, 2023. Without a new
nonreporting entities. agreement, these employees will not receive a
compensation increase in 2023-24. The Legislature
IS/IT Infrastructure and Staffing
likely will be asked to ratify a new labor agreement
Consider Expanding Use of Shared Service
with Local 1000 at some point this year. While we
Contracts for IS Services. One option the
will not know the content of a future agreement
Legislature could consider, consistent with a
with Local 1000 until it has been submitted to
recent recommendation on IS proposals in the
the Legislature for review, it is possible that such
Governor’s 2023-24 budget, is to require CDT to
an agreement could include provisions aimed at
prioritize shared service contracts for IS services
addressing recruitment and retention issues among
as part of its IT contract consolidation efforts
these staff.
to reduce service costs and generate savings.
www.lao.ca.gov 19
AN LAO REPORT
Given the consistent responses we received confidential and/or sensitive. Given the need to
from nonreporting entities about the difficulties in balance more visibility into some network traffic
recruiting, training, and retaining IS staff, this option with the need to maintain the confidentiality of
could have broader benefits to other state entities other traffic, the Legislature could request that
that may be facing similar challenges. the evaluation be presented to relevant budget/
Consider Monitoring State Data Center Rate policy committee staff and propose next steps for
Reassessment Process for IT Services. Another legislative consideration.
option the Legislature could consider is to monitor Consider Directing Administration to Evaluate
the progress of the rate reassessment process for Division of IT Procurement Responsibilities.
the State Data Center that is currently underway Another option the Legislature could consider,
to verify that IT services hosted by the State Data particularly for smaller nonreporting entities
Center will be comparable both in levels of service with fewer procurement staff but consistent
and price to major private vendors. Similar to the interaction with DGS for routine IT purchases,
previous option, we offer this option because is to request that CDT and DGS evaluate their
nonreporting entities’ hosting of applications and current division of IT procurement responsibilities
systems on the State Data Center increases CDT’s and identify opportunities to streamline routine
visibility into those entities’ IS programs. IT procurements. These opportunities could
Consider Mandating Certain Network Traffic include the consolidation of IT goods and services
Be Directed to CDT’s SOC for Monitoring. procurement authority under CDT, increases in the
Another option the Legislature could consider is to dollar amount thresholds to delegate more IT goods
request that CDT, in consultation with nonreporting and services purchases back to state entities, and
entities, evaluate what network traffic from other administrative changes that could reduce the
nonreporting entities could be directed to its SOC. amount of time to complete IT procurements. The
Network traffic directed from nonreporting entities Legislature also could request that CDT and DGS
to CDT’s SOC can be monitored for potential present the results of their evaluation to relevant
cyberattacks and threats. However, nonreporting budget/policy committee staff and propose next
entities might deem some network traffic to be steps for legislative consideration.
20 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
APPENDIX: MAJOR AUTHORITIES RELEVANT
TO THE REPORT
In this appendix, we provide federal and state system authorization before transferring data; and
authorities that are relevant to this report. We documentation of remote access implementation
acknowledge that there are other authorities from guidance, requirements, and restrictions prior
federal entities and industry organizations that to authorization, respectively. The latest revision
state entities (including nonreporting entities) to NIST SP 800-53 is Revision 5. As with FIPS,
must follow. We focus on major authorities reporting entities follow many state IS policies,
that inform our assessment and options for procedures, and standards based on NIST
legislative consideration. SP 800-53, while nonreporting entities are
required by AB 2135 to follow Revision 5 of NIST
Federal Authorities
SP 800-53 and all successor publications.
Federal Information Processing Standards
State Authorities
(FIPS). FIPS are guidelines and requirements
for federal computer systems developed by the Relevant Government Code Sections. Several
National Institute for Standards and Technology sections of the Government Code are relevant to
(NIST). Many state and local government entities, the definition of “state agency” and “state entity”
as well as private companies, voluntarily use in the California Department of Technology (CDT)
these standards to guide the development and Office of Information Security’s (OIS’) statutory
implementation of their information security (IS) authority. Other sections establish the California
programs. Reporting entities follow several state Cybersecurity Integration Center (Cal-CSIC)
IS policies, procedures, and standards based on and require Cal-CSIC to develop a statewide
FIPS, while nonreporting entities are required by cybersecurity strategy.
Chapter 773 of 2022 (AB 2135, Irwin) to follow the
• Section 8586.5. Government Code Section
two FIPS below:
8586.5 contains the statutory authority
• FIPS 199. FIPS 199 contains standards for Cal-CSIC. This section identifies the
for federal agencies to use in categorizing Governor’s Office of Emergency Services as
the importance of their information and its administrator and leader; names a number
information systems based on their need of Cal-CSIC representatives from federal
for the information or systems’ availability, law enforcement entities, Cal-CSIC partner
confidentiality, and integrity if compromised. entities (that is, CDT, the California Highway
• FIPS 200. FIPS 200 specifies minimum Patrol, and the California Military Department
security requirements for federal information [CMD]), state education segments, and
and information systems, and provides other state entities; and requires that
a risk-based process for selecting the Cal-CSIC develop a statewide cybersecurity
security controls that are needed to meet strategy, which is reflected in the state’s first
these requirements. five-year IS roadmap—Cal-Secure. While
reporting entities are subject to the state’s
NIST Special Publication (SP) 800-53. NIST
IS governance structure and, thus, must
SP 800-53 catalogues privacy and security
report to Cal-CSIC and follow Cal-Secure,
controls for information systems to protect
nonreporting entities largely are not subject
against a variety of cyber risks and threats. Some
to this structure. However, based on our
examples of categories for these controls include
research (which we discuss in more detail in
account management, information exchange,
the report), many nonreporting entities receive
and remote access. Some examples of controls
and use threat intelligence from Cal-CSIC and
in these categories include disabling accounts
use Cal-Secure to guide their cybersecurity
based on certain criteria; verifying individual or
initiatives and technical capability investments.
www.lao.ca.gov 21
AN LAO REPORT
• Section 11000. Government Code Section entities to assert their independence from
11000 provides the definition of a state agency the authority of OIS including IS policies,
used across the executive branch’s agencies procedures, and standards issued by the
and departments. The statute states that office under Government Code Section
“‘state agency’ includes every state office, 11549.3. (Government Code Section
officer, department, division, bureau, board, 11549.3 refers to “[a]ll state entities defined
and commission.” Assembly Bill 2135 uses this in Section 11546.1.”) As we discuss in
definition to avoid any statutory interpretations more detail in our report, we only include
that could lead to inconsistencies in the nonreporting entities on our list for which
application of the bill’s amendments to it is clearer based on constitutional or
Government Code Section 11549.3 (that are statutory authorities that they are not “under
discussed in more detail below). This definition the direct authority of the Governor.”
of state agency applies to both reporting and » Definition of State Agency in OIS’
nonreporting entities across the Government Statutory Authority. Paragraph (e)
Code except, for example, in OIS’ statutory (1) defines state agency as referring to a
authority where different definitions of state list of specific state agencies such as the
agency and state entity are used (as we Environmental Protection Agency, Health
define below). and Human Services Agency, and Labor
• Section 11546.1. Part of OIS’ larger authority, and Workforce Development Agency.
Government Code Section 11546.1 requires Other agencies, however, are omitted
each state agency and state entity to have such as the Government Operations
a chief information officer and information Agency. This definition is narrower than
security officer with specific roles and the Section 11000 definition above, which
responsibilities. More importantly for leads to different statutory interpretations
this report, paragraph (e) includes two of OIS’ authority over certain agencies
subparagraphs with definitions for state and, by extension, certain entities. We do
agency and state entity. These definitions not include any nonreporting entities on
are cross-referenced in key sections of OIS’ our list (which we provide in the report)
statutory authority. For example, Government based on their agency’s omission from
Code Section 11549.3, which we describe this definition, but at least some entities
in more detail below, requires state entities (based on different statutory interpretations)
meeting the definition in Section 11546.1(e) could be considered nonreporting entities
(2) (and not defined as state agencies if their state agency is omitted from the list
in paragraph [e][1]) to comply with state and their reporting relationship with the
IS policies, procedures, and standards. Governor is not clear.
We provide more information about the
• Section 11549.3. Government Code Section
definitions below:
11549.3 is one of the sections outlining
» Definition of State Entity in OIS’ Statutory OIS’ statutory authority. Section 11549.3(a)
Authority. Paragraph (e)(2) defines a state
identifies the responsibilities of OIS and
entity as “an entity within the executive
states that these are to include the creation,
branch that is under the direct authority
issuance, and maintenance of IS policies,
of the Governor, including, but not limited
procedures, and standards. Paragraph (b) of
to, all departments, boards, bureaus,
this section requires that reporting entities (that
commissions, councils, and offices that
is, those that meet the definition of state entity
are not defined as ‘state agency’ pursuant
in Section 11546.1[e][2]) comply with these
to paragraph (1).” Different statutory
and other filing requirements and incident
interpretations of the phrase “under the
notification protocols required by OIS. For this
direct authority of the Governor” lead some
report, we focus on the amendments made to
22 LEGISLATIVE ANALYST’S OFFICE
AN LAO REPORT
Section 11549.3 contained in paragraph (f) that State Administrative Manual (SAM) Section
are specific to nonreporting entities. 5300. SAM contains statewide policies, procedures,
and requirements developed and issued by,
» AB 2135. Paragraph (f) was added to
for example, CDT, the Department of Finance,
Government Code Section 11549.3 to
and DGS. Section 5300 contains the state’s IS
require every state agency as defined
policies, including those related to compliance
in Government Code Section 11000 not
reporting (Section 5330.2), IS program metrics
subject to Section 11549.3(b) (that is,
(Section 5305.9), and specific security controls.
nonreporting entities) to implement policies,
Reporting entities follow the state IS policies in SAM
procedures, and standards that adhere to
Section 5300. Nonreporting entities do not, unless
FIPS 199 and 200, and NIST SP 800-53,
they “voluntarily comply” with state IS policies,
Revision 5. Also, nonreporting entities
procedures, and standards (a concept we discuss in
are required to perform an independent
more detail in the report).
security assessment (ISA) every two years
Statewide Information Management Manual
that assesses the policies, procedures,
(SIMM) Section 5300. SIMM contains CDT’s
and standards they implemented pursuant
procedures as well as forms, instructions, and
to this section. Nonreporting entities
templates for compliance with IS and IT policies in
are permitted to use state IS policies,
SAM. In this report, we focus on two SIMM sections:
procedures, and standards instead of
SIMM 5305—the Risk Register and POAM—and
federal authorities and use CMD instead
SIMM 5330-B—IS and Privacy Program Compliance
of, for example, third-party vendors for
Certification. Reporting entities follow the state
their ISAs. Finally, nonreporting entities are
IS procedures as well as forms, instructions, and
required to certify annually to legislative
templates in SIMM Section 5300. Nonreporting
leadership, by February 1, their compliance
entities do not, unless they voluntarily comply
with federal or state IS policies, procedures,
with state IS policies, procedures, and standards.
and standards, including the submission
However, nonreporting entities are required by
of a plan of action and milestones (POAM)
AB 2135 to submit two IS compliance documents
(explained in more detail below).
annually (the compliance certification and POAM)
Public Contract Code Sections 12100-12113.
which are substantially similar in content and format
Public Contract Code Sections 12100-12113
to the two SIMM sections below:
delineate between the information technology
• SIMM 5305. The POAM and risk register
(IT) procurement process responsibilities of CDT
identify areas of IS noncompliance or
and the Department of General Services (DGS).
weaknesses, assets that are at risk, the
Paragraphs (b)-(e) in Section 12100 provide
entity’s response to the risk as reflected in
CDT with authority over contracts for IT goods
controls or plans of action, and any barriers
and services related to IT projects as well as
or constraints on mitigation of the risk. Some
telecommunications goods and services, while
information about future budget requests
paragraphs (f)-(g) provide DGS with authority over
that are required to mitigate risk or remediate
contracts for all other IT goods and services. The
areas of noncompliance or weaknesses is
remainder of the sections provide specific direction
also provided.
on particular procurement definitions, objectives,
and policies. All reporting entities must follow IT • SIMM 5330-B. The compliance certification
procurement processes as delineated in these attests that an entity is compliant with the
sections of the Public Contract Code, while some policies, procedures, and standards in the
nonreporting entities also follow these processes. IS sections of SAM and SIMM. This includes
Other nonreporting entities have more flexibility in state entity leaders’ acknowledgment of
their IT procurement processes and/or do not use risks identified through ISAs and other
CDT and/or DGS for their procurements. documentation and oversight mechanisms.
These certifications are due on an
annual basis.
www.lao.ca.gov 23
AN LAO REPORT
LAO PUBLICATIONS
This report was prepared by Brian Metzker, and reviewed by Mark C. Newton and Carolyn Chu. The Legislative
Analyst’s Office (LAO) is a nonpartisan office that provides fiscal and policy information and advice to the Legislature.
To request publications call (916) 445-4656. This report and others, as well as an e-mail subscription service, are
available on the LAO’s website at www.lao.ca.gov. The LAO is located at 925 L Street, Suite 1000, Sacramento,
California 95814.
24 LEGISLATIVE ANALYST’S OFFICE